CVE-2024-47115: IBM AIX command execution
Published Dec 5, 2024
·Updated
IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
Other sources
IBM AIX could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
— IBM
Affected Software
6 affected components
IBM AIX<=7.2, 7.3
IBM VIOS<=3.1, 4.1
IBM VIOS=3.1
IBM VIOS=4.1
IBM AIX=7.2
IBM AIX=7.3
Event History
Dec 5, 2024
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Dec 7, 2024
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-47115?
CVE-2024-47115 has been rated as high severity due to the potential for arbitrary command execution by local users.
2
How do I fix CVE-2024-47115?
To fix CVE-2024-47115, users should apply the latest patches and updates provided by IBM for AIX and VIOS.
3
Who is affected by CVE-2024-47115?
CVE-2024-47115 affects IBM AIX versions 7.2, 7.3 and VIOS versions 3.1 and 4.1.
4
What kind of commands can be executed due to CVE-2024-47115?
Due to CVE-2024-47115, local users can execute arbitrary commands, which can compromise system integrity.
5
Is remote exploitation possible with CVE-2024-47115?
No, CVE-2024-47115 requires local access to the system for exploitation.